--- gem: omniauth-oauth2 cve: 2012-6134 osvdb: 90264 url: http://www.osvdb.org/show/osvdb/90264 title: Ruby on Rails omniauth-oauth2 Gem CSRF vulnerability date: 2012-09-08 description: | The omniauth-oauth2 Ruby Gem contains a flaw that allows an attacker to inject values into a user's session through a CSRF attack. cvss_v2: 6.8 patched_versions: - ">= 1.1.1"